Privacy
Last updated 1 August 2026
Firnline is used by one person, to look at that person’s own bank accounts. This page describes what it does with that data.
Who is responsible
Firnline is operated by a private individual for personal, non-commercial use. Contact for data protection matters: moritz.santoni@icloud.com.
What data is accessed
- Account details — account identifiers, holder name, currency, product type.
- Balances.
- Transaction history — dates, amounts, counterparty names and payment references.
Access is read-only. Firnline cannot initiate payments or modify anything at the bank.
How it is accessed
Through Enable Banking, a licensed account information service provider operating under PSD2. Authentication happens on the bank’s own pages; Firnline never sees or stores bank login credentials. Each bank connection requires explicit consent, which expires after a period set by the bank (typically 90 to 180 days) and must be renewed.
Where it is stored
On infrastructure controlled by the operator. Data is retained indefinitely, because the point of the application is a long-run financial history — banks themselves only expose a limited window.
Who it is shared with
Nobody. The data is not sold, published, shared with third parties, used for advertising or profiling, or used to train any model. The only external party in the chain is Enable Banking, which acts as the regulated intermediary to the banks and has its own privacy policy.
Legal basis
Consent (Art. 6(1)(a) GDPR), given by the account holder at each bank, and processing of the account holder’s own data for purely personal purposes.
Withdrawing consent
Bank consents can be revoked at any time — through Enable Banking’s consent portal, in the bank’s own online banking, or by emailing the address above. Revoking a consent stops further access immediately.
Your rights
As the sole user is also the operator and the data subject, the usual GDPR rights — access, rectification, erasure, portability, objection — are exercised directly. If you believe your data has somehow ended up here, write to moritz.santoni@icloud.com and it will be deleted.